Vulnerability Management

New CIFSwitch vulnerability allows Linux privilege escalation

Closeup of a mobile phone screen with logo lettering of linux on computer keyboard

Bleeping Computer reports that a newly discovered local privilege escalation vulnerability, dubbed "CIFSwitch," has been found in the Linux kernel. This flaw could potentially allow attackers to forge CIFS authentication key descriptions and abuse the kernel's key request mechanism to gain root privileges.

The CIFSwitch vulnerability, which was discovered by SpaceX Security Engineer Asim Viladi Oglu Manizada, impacts multiple Linux distributions that use vulnerable versions of the Linux kernel's CIFS subsystem and the cifs-utils package. The issue arises because the Linux kernel's CIFS subsystem fails to verify that cifs.spnego key requests originate from the kernel's CIFS client. This allows an unprivileged user to create a forged request, tricking the root-privileged cifs.upcall helper into trusting attacker-controlled fields. By manipulating these fields, an attacker can trigger a namespace switch and load a malicious NSS module, ultimately achieving root code execution.

The vulnerability was introduced approximately 19 years ago and its exploitability depends on factors like kernel and cifs-utils versions, user namespace availability, and security policies. Several Linux distributions, including Linux Mint, CentOS Stream 9, Rocky Linux 9, AlmaLinux 9, Kali Linux, and SLES 15 SP7, are confirmed to be vulnerable with default configurations. A kernel patch has been released to address the issue, and users are advised to disable CIFS modules or cifs-utils if unused, and disable unprivileged user namespaces.

Source: Bleeping Computer

Related Events

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds